Privacy policy
We keep the leakage, not the identities.
Effective July 17, 2026 · Last review July 17, 2026
No tracking
No analytics, ads pixels, heatmaps, session recording, or tracking cookies.
Two-layer privacy intake
The dealer-side tool removes personal information before upload; MIQ intake independently rejects detectable personal information before storage. Import templates are designed to exclude customer names, addresses, phones, emails, and SINs.
Canada-first
Client operational data is designed for AWS ca-central-1 residency and tenant isolation.
1. Scope
This Privacy Policy explains how Mechanus IQ Ltd. collects, uses, discloses, protects, and retains personal information through the public website at mechanusiq.com, contact forms, inbound business communications, and related security systems.
Paid services, pilots, diagnostics, and data processing for a client organization are also governed by the signed client agreement. If a signed client agreement conflicts with this Privacy Policy for client operational data, the signed agreement controls for that client engagement.
Mechanus IQ is built for Canadian dealership operations. Privacy obligations may include PIPEDA and, where applicable, provincial private-sector privacy laws such as British Columbia PIPA, Alberta PIPA, and Quebec private-sector privacy legislation.
2. What we do not collect
We do not run Google Analytics, Google Tag Manager, Meta Pixel, Hotjar, Clarity, Segment, Mixpanel, Amplitude, PostHog, Plausible, Fathom, session replay, heatmapping, behavioural advertising, fingerprinting, or third-party marketing telemetry on the Site.
We do not set tracking cookies. We do not sell personal information. We do not use Site visitors for advertising profiles. We do not train AI models on Site visitor information. Client data is not used for model training unless a written controlled-learning authority is executed under the client agreement.
Two layers stand between personal information and Mechanus IQ storage. First, a Mechanus IQ-built cleaning tool runs on dealer equipment to remove personal information from DMS exports before upload. Second, Mechanus IQ processes authorized operational exports through intake screening that independently rejects detectable personal information before storage. Export templates are designed to exclude customer names, addresses, phone numbers, email addresses, social-insurance numbers, and equivalent direct identifiers. Employee names, DMS user IDs, and personnel codes are not accepted on the operational upload path. Any staff-coded workflow is activated only under separate written approval.
3. What we collect
If you contact us, we may collect the information needed to respond: your name, business email, phone number if provided, organization, role, province or region, message content, and any information you choose to include in the communication.
If you request a pilot, diagnostic, briefing, or commercial conversation, we may collect business-contact information, dealership or group information, scheduling information, stated operational priorities, and the history of our communications with you.
Hosting and security providers may process request metadata such as IP address, user agent, requested URL, timestamp, referrer, device and browser indicators, protocol details, bot-score indicators, and security-event metadata under their own service settings for site operation, security, abuse prevention, incident response, and legal preservation where appropriate, not behavioural advertising. The Mechanus IQ /trap/* control may use request-local information to block a trap request but does not persist that request metadata; its one-day aggregate is described below.
When a dealer becomes a client, Mechanus IQ may process operational dealership data described in the signed client agreement, such as deal logs, funding reports, F and I summaries, service repair-order logs, inventory reports, cancellation records, warranty records, and canonicalized operational versions of those records. The client agreement governs that processing.
4. Why we use information
Mechanus IQ uses personal information only for limited business purposes:
- to respond to inquiries and maintain ordinary business-contact records;
- to assess pilot, diagnostic, or commercial fit;
- to schedule calls, prepare conversations, and administer requested communications;
- to operate, secure, troubleshoot, and improve the Site without behavioural tracking;
- to detect, investigate, prevent, and respond to scraping, bot activity, abuse, security events, or unauthorized access;
- to administer client agreements, security requirements, and data-processing obligations; and
- to comply with legal, regulatory, accounting, tax, insurance, dispute, evidence-preservation, and governance obligations.
5. Disclosure
We do not sell personal information. We do not disclose personal information for third-party advertising. We do not share client operational data with other clients.
We may disclose limited information to service providers that help us operate the Site, secure the Site, process contact requests, host infrastructure, provide email or scheduling services, maintain records, or support legal and accounting administration. Service providers are permitted to use the information only for the service they provide to Mechanus IQ.
We may disclose information where required or permitted by law, including to courts, regulators, law enforcement, professional advisers, insurers, auditors, or counterparties where necessary for legal claims, security incidents, evidence preservation, contract enforcement, corporate transactions, or compliance obligations.
6. Residency and cross-border handling
Client source uploads, storage, logs, evidence, backups, and non-LLM processing are designed for AWS ca-central-1 residency, with tenant isolation and no cross-client reuse unless the client expressly agrees in writing.
The public website is served through Cloudflare and other ordinary internet infrastructure. Website request metadata and security metadata may be processed by those providers in the jurisdictions where they operate, subject to contractual, technical, and organizational safeguards. This edge-security metadata is separate from client operational data.
Any enabled model-assisted inference path must be disclosed according to the client agreement and applicable workflow. Analytical summarization of findings may use a large language model through Amazon Bedrock, and that inference can route through cross-region inference to United States regions. Content sent on that path must have passed intake stripping and PII redaction.
Third-party development and support tooling is not a production subprocessor for client operational data, raw dealer source uploads, customer PII, or dealer-identifying confidential data. Any use of that tooling is restricted to code, public or legal text, non-confidential architecture, synthetic examples, or sanitized excerpts unless a written client-approved and counsel-reviewed process expands it.
Client data is not used to train, fine-tune, or improve AI models by default. Any controlled-learning path requires written authority, signals proven eligible under the governed intake and privacy controls, and documented contractual controls under the client agreement.
7. Retention
Business-contact records are retained for as long as needed to manage the relationship, respond to the inquiry, maintain ordinary business records, and satisfy legal or governance requirements. Non-client inquiries are normally removed or archived after they are no longer operationally required.
Website security retention depends on the record class. The periods below describe Mechanus IQ's current application-level bot-trap controls.
| Record class | Current handling | Application-level period |
|---|---|---|
| Ordinary website requests | Under the current /trap/* route, ordinary page requests are not written to the bot-trap violation store. | No Mechanus IQ bot-trap violation store retention period. |
| Honeypot events under /trap/* | When a request reaches a /trap/* path and the security store write succeeds, a best-effort, non-identifying aggregate count is recorded for security review. No IP address, user-agent, requested URL, headers, TLS fingerprint, location, ASN, or visitor-derived identifier is written. | The hourly aggregate expires 1 day after the bucket was last updated. |
Provider-side edge records are separate from the Mechanus IQ bot-trap violation store. Cloudflare and other infrastructure providers may process and retain their own operational or security records under the applicable service settings and legal obligations; the periods above do not state or control those provider periods.
If a legal hold or preservation duty applies, a separately authorized preservation step must occur before the applicable application-level expiry. The bot-trap expiry control does not extend itself. Records are destroyed or de-identified when their identified security purpose is no longer being served and retention is no longer necessary for legal or business purposes, as required by applicable law.
Client operational data follows the signed client agreement and the applicable retention schedule. Destruction, export, hold, and preservation obligations are handled under that agreement.
8. Safeguards
Mechanus IQ uses administrative, technical, and physical safeguards appropriate to the sensitivity of the information. Safeguards may include access controls, least-privilege access, encrypted transport, tenant isolation, audit logging, security headers, Cloudflare edge controls, bot-trap controls, and documented incident-response procedures.
No internet system is perfectly secure. Mechanus IQ limits collection, avoids tracking, separates public website metadata from client operational data, provides a dealer-side tool that removes personal information before upload, and rejects detectable personal information at intake before storage.
Technical details are summarized at /platform/infrastructure/security.
9. Your rights and choices
Subject to applicable law and verification of identity, you may request access to personal information we hold about you, correction of inaccurate information, withdrawal of consent where consent is the basis for processing, deletion where legally available, or information about how your information has been used or disclosed.
Requests should be sent to privacy@mechanusiq.com. We respond within the legally required period, which is normally 30 days unless an extension or different statutory timeline applies.
If you have a concern that we cannot resolve, you may contact the Office of the Privacy Commissioner of Canada or, where applicable, the provincial privacy regulator with jurisdiction over the matter.
10. Marketing and communications
We may use business-contact information to respond to a request, continue an active business conversation, or send information directly related to the matter you raised. We do not add website visitors to behavioural advertising audiences.
If we send a commercial electronic message that requires unsubscribe functionality under applicable anti-spam law, we will include an unsubscribe method. You may also ask us to stop non-essential communications by contacting privacy@mechanusiq.com.
11. Children
The Site is a business-to-business website for dealership operators, lenders, professional advisers, and business reviewers. It is not directed to children, and we do not knowingly collect personal information from children through the Site.
12. Changes
We may update this Privacy Policy by posting a revised version with a new effective date. Changes apply prospectively from the effective date shown unless a different effective date is required by law.
13. Contact
Privacy inquiries and access requests: privacy@mechanusiq.com. Jurisdiction: British Columbia, Canada.
Legal and website-access questions may also be sent through the contact form at /start#contact.
Security posture
Technical safeguards, tenancy isolation, encryption posture, and incident-response controls are summarized at security posture.